steveloughran commented on PR #15171: URL: https://github.com/apache/iceberg/pull/15171#issuecomment-3825505395
Makes sense: it's up to the server to decide what to sign, as long as the final signature is valid. I'd like the referrer header to be stripped out in the example servlet FWIW; We use it for adding audit information with every request and it has no security ramifications -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
